"""TapeOutScan API: Python 3 standard library only. Set TOS_API_KEY and TOS_API_SECRET in your server environment before running. Never embed the secret in website JavaScript or a public repository. """ import hashlib import hmac import json import os import secrets import time import urllib.error import urllib.request # Sign the EXACT path + query sent to the server, including parameter order. target = '/v1/circuits?chainId=56&collection=30&limit=20' timestamp = str(int(time.time())) nonce = secrets.token_hex(16) message = '\n'.join(['GET', target, timestamp, nonce, hashlib.sha256(b'').hexdigest()]) signature = hmac.new(os.environ['TOS_API_SECRET'].encode(), message.encode(), hashlib.sha256).hexdigest() request = urllib.request.Request('https://tapeoutexplorer.com' + target, headers={ 'X-TOS-Key': os.environ['TOS_API_KEY'], 'X-TOS-Timestamp': timestamp, 'X-TOS-Nonce': nonce, 'X-TOS-Signature': signature, 'Accept': 'application/json', }) try: with urllib.request.urlopen(request, timeout=10) as response: payload = json.load(response) print(json.dumps(payload, ensure_ascii=False, indent=2)) except urllib.error.HTTPError as error: print('HTTP', error.code, 'Retry-After:', error.headers.get('Retry-After')) print(error.read().decode())